Vulnerabilità ed exploit · Supply chain
GitHub Actions è diventato un nastro trasportatore per il furto di secret Un commit di workflow malevolo in GitHub Actions non è un problema che riguarda solo il repository. Può trasformare CI in un sifone di credenziali che estrae secret memorizzati, dati di ambiente a breve durata del runner, credenziali dei metadati cloud, chiavi SSH e token OIDC che raggiungono altri sistemi cloud e SaaS dopo che il repository stesso è stato patchato.
4 fonti · 27 mag
Cronologia Fonti 27 mag Dark Reading
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
In just six hours, the campaign quietly pushed malware to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.
originale 26 mag CSO Online
GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos
Researchers say the campaign abused compromised access tokens and deploy keys to inject malicious GitHub Actions workflows into thousands of public repositories.
originale 25 mag SecurityWeek
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
originale Part of the PlainSec briefing for 2026-05-25
Every edition of this story: GitHub Actions è diventato un nastro trasportatore per il furto di secret
Altro da oggi
Vulnerabilità ed exploit · Supply chain
GitHub Actions è diventato un nastro trasportatore per il furto di secret Un commit di workflow malevolo in GitHub Actions non è un problema che riguarda solo il repository. Può trasformare CI in un sifone di credenziali che estrae secret memorizzati, dati di ambiente a breve durata del runner, credenziali dei metadati cloud, chiavi SSH e token OIDC che raggiungono altri sistemi cloud e SaaS dopo che il repository stesso è stato patchato.
4 fonti · 27 mag
Cronologia Fonti 27 mag Dark Reading
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
In just six hours, the campaign quietly pushed malware to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.
originale 26 mag CSO Online
GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos
Researchers say the campaign abused compromised access tokens and deploy keys to inject malicious GitHub Actions workflows into thousands of public repositories.
originale 25 mag SecurityWeek
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
originale Part of the PlainSec briefing for 2026-05-25
Every edition of this story: GitHub Actions è diventato un nastro trasportatore per il furto di secret
Altro da oggi